CVE-2020-2509
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 34.2% 백분위 98.2% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.05.02
- 공개일
- 2021.04.17
CISA KEV에 등록된 실제 악용 확인 취약점
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
공급사 QNAP
제품 QNAP Network-Attached Storage (NAS)
영향 버전 unspecified, < 4.2.6, >= 4.3.5 < 4.3.6, >= 4.4.0 < 4.5.1, 4.2.6, 4.3.3.0174, 4.3.3.0868, 4.3.3.0998, 4.3.3.1051, 4.3.3.1098, 4.3.3.1161, 4.3.3.1252, 4.3.3.1315, 4.3.3.1386, 4.3.3.1432, 4.3.4.0358, 4.3.4.0370, 4.3.4.0372, 4.3.4.0374, 4.3.4.0387
수정 버전 4.2.6, 4.3.6, 4.5.1, h4.5.1
Apply updates per vendor instructions.
조치 기한: 2022.05.02CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-77, CWE-78
KEV 등록일 2022.04.11
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2020-2509
EPSS 데이터 기준일 2026.06.27